Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareAmadey | Amadey has collected the computer name and OS version from a compromised machine. |
| T1082 System Information Discovery |
MalwareProxysvc | Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics. |
| T1082 System Information Discovery |
MalwareOrz | Orz can gather the victim OS version and whether it is 64 or 32 bit. |
| T1082 System Information Discovery |
MalwareNOKKI | NOKKI can gather information on the operating system on the victim’s machine. |
| T1082 System Information Discovery |
Malwareyty | yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command |
| T1082 System Information Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the OS and computer name. |
| T1082 System Information Discovery |
MalwareStuxnet | Stuxnet collects system information including computer and domain names, OS version, and S7P paths. |
| T1082 System Information Discovery |
MalwareIronWind | IronWind can capture the OS version and computer name of the compromised host. |
| T1082 System Information Discovery |
MalwareRotaJakiro | RotaJakiro executes a set of commands to collect device information, including `uname`. Another example is the `cat /etc/*release | uniq` command used to collect the current OS distribution. |
| T1082 System Information Discovery |
MalwareGet2 | Get2 has the ability to identify the computer name and Windows version of an infected host. |
| T1082 System Information Discovery |
MalwarePOWRUNER | POWRUNER may collect information about the system by running |
| T1082 System Information Discovery |
MalwareSharpStage | SharpStage has checked the system settings to see if Arabic is the configured language. |
| T1082 System Information Discovery |
MalwareSardonic | Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands. |
| T1082 System Information Discovery |
MalwareHALFBAKED | HALFBAKED can obtain information about the OS, processor, and BIOS. |
| T1082 System Information Discovery |
MalwareMisdat | The initial beacon packet for Misdat contains the operating system version of the victim. |
| T1082 System Information Discovery |
MalwareEmissary | Emissary has the capability to execute ver and systeminfo commands. |
| T1082 System Information Discovery |
MalwareKEYMARBLE | KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, and time elapsed since system start. |
| T1082 System Information Discovery |
MalwareBUBBLEWRAP | BUBBLEWRAP collects system information, including the operating system version and hostname. |
| T1082 System Information Discovery |
MalwareHAWKBALL | HAWKBALL can collect the OS version, architecture information, and computer name. |
| T1082 System Information Discovery |
MalwareUrsnif | Ursnif has used Systeminfo to gather system information. |
| T1082 System Information Discovery |
MalwareThreatNeedle | ThreatNeedle can collect system profile information from a compromised host. |
| T1082 System Information Discovery |
MalwareRansomHub | RansomHub can retrieve information about virtual machines. |
| T1082 System Information Discovery |
MalwareZLib | ZLib has the ability to enumerate system information. |
| T1082 System Information Discovery |
MalwareRedLeaves | RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information. |
| T1082 System Information Discovery |
MalwareTsundere Botnet | Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information. |
| T1082 System Information Discovery |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number. |
| T1082 System Information Discovery |
MalwareFelismus | Felismus collects the system information, including hostname and OS version, and sends it to the C2 server. |
| T1082 System Information Discovery |
MalwareZeus Panda | Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system. |
| T1082 System Information Discovery |
MalwareHavoc | Havoc can gather system information including hostname, domain, and OS details. |
| T1082 System Information Discovery |
MalwareCARROTBAT | CARROTBAT has the ability to determine the operating system of the compromised host and whether Windows is being run with x86 or x64 architecture. |
| T1082 System Information Discovery |
MalwareGravityRAT | GravityRAT collects the MAC address, computer name, and CPU information. |
| T1082 System Information Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected OS type, hostname and system version through the "pay" module. InvisibleFerret has also queried the victim device using Python scripts to obtain the User and Hostname. |
| T1082 System Information Discovery |
MalwareBankshot | Bankshot gathers system information, network addresses, and the operation system version. |
| T1082 System Information Discovery |
MalwareHAPPYWORK | can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path. |
| T1082 System Information Discovery |
MalwarePLAINTEE | PLAINTEE collects general system enumeration data about the infected machine and checks the OS version. |
| T1082 System Information Discovery |
MalwarePony | Pony has collected the Service Pack, language, and region information to send to the C2. |
| T1082 System Information Discovery |
MalwareWinMM | WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server. |
| T1082 System Information Discovery |
MalwareTONESHELL | TONESHELL has the ability to retrieve the name of the infected machine. |
| T1082 System Information Discovery |
MalwareKasidet | Kasidet has the ability to obtain a victim's system name and operating system version. |
| T1082 System Information Discovery |
MalwareOceanSalt | OceanSalt can collect the computer name from the system. |
| T1082 System Information Discovery |
MalwareBrave Prince | Brave Prince collects hard drive content and system configuration information. |
| T1082 System Information Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has collected data from the SMBIOS firmware table using `GetSystemFirmwareTable`. |
| T1082 System Information Discovery |
MalwareAppleSeed | AppleSeed can identify the OS version of a targeted system. |
| T1082 System Information Discovery |
MalwaremacOS.OSAMiner | macOS.OSAMiner can gather the device serial number. |
| T1082 System Information Discovery |
MalwareNETWIRE | NETWIRE can discover and collect victim system information. |
| T1082 System Information Discovery |
MalwareEnvyScout | EnvyScout can determine whether the ISO payload was received by a Windows or iOS device. |
| T1082 System Information Discovery |
MalwareSslMM | SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date. |
| T1082 System Information Discovery |
MalwareIMAPLoader | IMAPLoader uses WMI queries to gather information about the victim machine. |
| T1082 System Information Discovery |
MalwareGomir | Gomir collects information on infected systems such as hostname, username, CPU, and RAM information. |
| T1082 System Information Discovery |
MalwareAria-body | Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.